HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Stealthy Kernel‑Mode Backdoor Daxin Resurfaces in Taiwan, Paired with New Pre‑Auth Backdoor Stupig

Symantec found the China‑linked kernel rootkit Backdoor.Daxin active on a Taiwanese high‑tech manufacturer in 2026, alongside a novel pre‑auth backdoor Stupig. The incident highlights gaps in log‑based detection and the need for continuous control evidence to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 July 15, 2026· 📰 security.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
security.com

Stealthy Kernel‑Mode Backdoor Daxin Resurfaces in Taiwan, Paired with New Pre‑Auth Backdoor Stupig

What Happened — Symantec’s Threat‑Hunter team discovered the China‑linked kernel‑mode rootkit Backdoor.Daxin operating on a Taiwanese subsidiary of a multinational high‑tech manufacturer in May 2026. The same host also contained a previously undocumented backdoor, Backdoor.Stupig, which injects a malicious keyboard‑layout DLL into winlogon.exe to execute commands as SYSTEM from the Windows logon screen, bypassing audit logs.

Why It Matters for Compliance & Audit Readiness

  • The persistence technique evades traditional log‑based detection, highlighting gaps in access‑control monitoring and audit‑trail completeness required by SOC 2 CC6.
  • Long‑term, undetected compromise underscores the need for continuous control evidence collection (e.g., endpoint telemetry, privileged‑session logging) to prove that security controls are operating effectively over time.
  • Mapping these advanced TTPs to your control framework helps generate defensible audit evidence and demonstrates due‑diligence in a third‑party risk program.

Who Is Affected — High‑tech manufacturing, OEM subsidiaries, and any organization running Windows workstations/servers in high‑value environments.

Recommended Actions

  • Align endpoint‑monitoring and privileged‑access controls with SOC 2 CC6 requirements; enable continuous collection of logon‑session data and kernel‑level telemetry.
  • Conduct a control‑mapping exercise to ensure evidence of “pre‑authentication activity detection” is captured and retained for audit review.
  • Validate that third‑party risk assessments include verification of kernel‑mode driver integrity and supply‑chain provenance.

Source: Broadcom Symantec Blog – Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

Technical Notes

  • Attack vector: Kernel‑mode driver backdoor (Daxin) + pre‑auth DLL injection (Stupig).
  • Persistence: Winlogon.exe DLL load, no logon audit event.
  • Compile timestamps: Early 2013 (both samples).
  • Detection gap: Host telemetry only reported in May 2026, suggesting up to 13 years of undetected presence.
📰 Original Source
https://www.security.com/threat-intelligence/daxin-returns-stupig

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →